ecommerce.tiktok-seller-detail

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a Python script (scripts/tiktok_seller_detail.py) to execute API calls and handle data. The documentation instructs users to run the script via python scripts/tiktok_seller_detail.py '<JSON parameters>'. While this involves shell execution, it is standard for local agent tooling and operates within the vendor's own infrastructure.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations using Python's urllib.request to connect to ${NEXSCOPE_PROXY_BASE}/api/v1/tools/research/echotik/sellerDetail. These requests are directed to the vendor's established API proxy for fetching TikTok analytics data and are authenticated via the NEXSCOPE_API_KEY environment variable.
  • [DATA_READ_WRITE]: The script implements a logging and caching mechanism that writes API responses to the local filesystem under <cwd>/nexscope/. It dynamically determines a writable directory, preferring the current project directory or the user's home directory. This is used for session management and credit optimization (24h caching).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:45 AM
Security Audit — agent-trust-hub — ecommerce.tiktok-seller-detail